Edit report at https://bugs.php.net/bug.php?id=67363&edit=1
ID: 67363
User updated by: mg at artigo dot pl
Reported by: mg at artigo dot pl
Summary: Unserialize corrupts data
Status: Open
Type: Bug
Package: Variables related
Operating System: Irrelavant
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
The information in comments is irrelevant. The corruption does not occur, because the object itself
changes, but it is the same with any change of it - only some combinations of values cause
corruption. The difference in serialize output is related to classes serialize method which removes
the "parent" field.
Previous Comments:
------------------------------------------------------------------------
[2014-05-30 17:18:50] mg at artigo dot pl
It turns out I simplified Case 1 too much, I attach the whole information again:
------------
It seems that serialize function has something to do with it. It returns different outputs in the
following cases:
Case 1:
unserialize(serialize($data));
echo serialize($data); // output:
https://dl.dropboxusercontent.com/u/11435743/php/serialize_unserialize_serialize.txt
Case 2:
echo serialize($data); // output:
https://dl.dropboxusercontent.com/u/11435743/php/serialize.txt
Data corruption DOES NOT occur when I run unserialize on the output of Case 1.
Data corruption DOES occur when I run unserialize on the output of Case 2.
Example of the currupted outputs are attached in the original post.
To summarize: putting additional unserialize(serialize($data)); before serialize($data); seems to
workaround the corruption by resulting in a different output of the second call of serialize
function. This output can then be safely passed to unserialize function and the corruption does not
occur.
------------------------------------------------------------------------
[2014-05-30 17:00:41] mg at artigo dot pl
Please excuse the error in the sentence:
I attach this example, because data corruption does NOT seem to occur in Case 1. It seems only to
occur in Case 2.
------------------------------------------------------------------------
[2014-05-30 16:55:42] mg at artigo dot pl
It seems that serialize function has something to do with it, it gives different outputs:
Case1, output of:
serialize(unserialize(serialize($data)));
https://dl.dropboxusercontent.com/u/11435743/php/serialize_unserialize_serialize.txt
Case 2, output of:
serialize($data)
https://dl.dropboxusercontent.com/u/11435743/php/serialize.txt
I attach this example, because data corruption does seem to occur in Case 1. It seems only to occur
in Case 2.
------------------------------------------------------------------------
[2014-05-30 15:26:26] mg at artigo dot pl
Description:
------------
Unserialize method of PHP corrupts random values inside serialized objects. Corrupted value may be a
string (in this case it is clearly visible on the website).
We have encountered this issue on every PHP version from 5.3 to 5.5
and multiple environments (linux, windows). PHP 5.2 was free from this bug (version switching proved
it).
The corruption occurs only on some value combinations, for example after we change one of the string
values the corruption does not appear, when we changed it back: the corruption occurs again.
The type of object does not matter, it often happens for stdClass.
Please check an example object, which was used in Test script:
https://dl.dropboxusercontent.com/u/11435743/php/load.txt
Please compare it with the object which is an output of unserialize function.
https://dl.dropboxusercontent.com/u/11435743/php/load_corrupt.txt
Clearly one of the values has changed:
Instead of "Make-up & Styling", value is now: "Make-up ' Sty
Please note that pasting of the corrupt string works only until letter "y", please check
the load_corrupt.txt file to see the full string.
The corruption may have a various form, it can be an additional letter, changed letter, for example:
"Stylid" instead of "Styling".
Test script:
---------------
file_put_contents('load.txt', $data); // correct object
file_put_contents('load_corrupt.txt', serialize(unserialize($data))); // one of the value
was changed by unserialize, we serialize it back to save it to file
Expected result:
----------------
"make-up-styling";s:4:"name";s:17:"Make-up & Styling"
Actual result:
--------------
s:15:"make-up-styling";s:4:"name";s:17:"Make-up ' Sty
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67363&edit=1